Improper Data Handling The advisory has been revoked - it doesn't affect any version of package wordpress  (opens in a new tab)


Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
13.71% (96th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU1904-WORDPRESS-629140
  • published25 Nov 2014
  • disclosed25 Nov 2014

Introduced: 25 Nov 2014

CVE-2014-9034  (opens in a new tab)
CWE-19  (opens in a new tab)

Amendment

The Ubuntu security team deemed this advisory irrelevant for Ubuntu:19.04.

NVD Description

Note: Versions mentioned in the description apply only to the upstream wordpress package and not the wordpress package as distributed by Ubuntu.

wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.